Gestion d’entreprise · Internal Audit and GRC
Gouvernance, risques et conformité appuyés sur des preuves, pas sur une présentation
The GRC layer on top of Compliance Control: an audit universe prioritized by risk, an annual plan approved by the committee, engagements with an audit program and reviewed working papers, findings with a management action plan and follow-up, three lines of defense declared, key risk indicators with risk appetite thresholds read from the real operating modules, and the ISO 27001, COSO and SOX libraries mapped onto the controls the company already has.